Security
This page is maintained by pörtner consulting to answer common security questions about EDI EXPLAINER. It describes the controls in place today and is not an independent certification or audit report.
Last updated: 1 July 2026
Shared responsibility
Our hosting platform provides infrastructure, managed database, authentication and transport security. pörtner consulting is responsible for application logic, access rules and data handling. You remain responsible for who you invite into your account, the documents you upload and your own credential hygiene.
Authentication and access
- E-mail and password sign-in plus Google single sign-on.
- Sessions are handled by the managed authentication service with rotating tokens.
- Every data table enforces row-level security so that records are only readable by their owning account.
- Roles are stored separately from user profiles and checked server-side; they cannot be changed from the browser.
Data protection in transit and at rest
- All traffic is served over HTTPS with modern TLS.
- Documents and analysis results are stored in a managed database with encryption at rest provided by the hosting platform.
- Server-side logic runs behind authenticated server functions; privileged database access is never exposed to the browser.
Document handling and AI
- Structural and syntactic validation runs deterministically on our own engine without leaving the platform.
- Only masked extracts are sent to the AI gateway for plain-language explanations.
- Your documents are not used to train models.
- Deleting an analysis removes the stored document content and its findings.
Reporting a vulnerability
Please report suspected vulnerabilities to edi-explainer@poertner-consulting.eu with the subject "Security". Include steps to reproduce and avoid accessing data that is not yours. We acknowledge reports and keep you informed while we investigate.
Security contact
- edi-explainer@poertner-consulting.eu
- Phone
- 06435 / 5480251
- Postal
- pörtner consulting, Im Bruch 31, 56414 Hundsangen